Data Access & Processing Disclosure

GDPR & Data Protection Compliance Schedule for the Shoptest Shopify Application. This document is incorporated into the Shoptest Terms of Service and describes exactly what data Shoptest accesses, stores, and does not access when you install the App.

Data Processing Agreement

Last updated: 21 September 2026

GDPR Article 28 processing terms between the Merchant (Controller) and Shoptest (Processor). This DPA is incorporated into and forms part of the Shoptest Terms of Service.

A signed counterpart of this DPA is available on request at legal@shoptest.ai. This public version is the standard terms; the signed copy matches this page unless we agree otherwise in writing.

  1. Parties and Background

This Data Processing Agreement ("DPA") is entered into between the Merchant that has accepted the Shoptest Terms of Service ("Merchant", "Controller") and the operator of the Shoptest application, Hyper Effekt sp. z o.o., a company registered in Poland under KRS number 0001118008, REGON 529220060, NIP 7831908473, with its registered office at ul. 27 Grudnia 5/5A, 61-737 Poznań, Poland ("Shoptest", "Processor", "Company").

  1. Definitions

  • "Merchant Personal Data" means any Personal Data processed by Shoptest on behalf of the Merchant in connection with the Service, as described in the Data Access & Processing Disclosure.

  • "Data Protection Laws" means the GDPR and any other applicable data protection or privacy law.

  • "Sub-processor" means any third party engaged by Shoptest to process Merchant Personal Data.

  • "Security Incident" means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Merchant Personal Data.

  • "Applicable Data Protection Law" means the GDPR, the UK GDPR, and US state privacy laws that apply to the processing, including the California Consumer Privacy Act as amended by the CPRA.

  • "Business Purpose" means providing the Shoptest service described in the Terms and the Data Access & Processing Disclosure: storefront testing, monitoring, alerting, and related support.

  1. Roles of the Parties

For Merchant Personal Data, the Merchant is the Controller and Shoptest is the Processor, within the meaning of Article 4 GDPR. Where Merchant Personal Data includes End Customer data that Shoptest incidentally processes, the Merchant remains Controller of that data and Shoptest processes it strictly as its Processor.

3A. US Privacy / Service Provider

Where US state privacy law applies (including the CPRA), Shoptest is a service provider (or contractor) to the Merchant, not a third party that "sells" or "shares" personal information.

Shoptest will:

  • process Merchant Personal Data only for the Business Purpose above;

  • not sell or share it, and not use it for cross-context behavioural advertising;

  • not retain, use, or disclose it outside the direct Merchant–Shoptest relationship, except as required by law or to the sub-processors listed on shoptest.ai/legal/subprocessors;

  • not combine it with personal information from other customers or from our own consumer products, except as needed to provide the Service (for example security, billing, or aggregate product improvement that does not identify the Merchant or any shopper);

  • not use Merchant content, screenshots, or logs to train our own or a sub-processor's foundation models;

  • tell the Merchant if we determine we can no longer meet these obligations.

The Merchant may take reasonable steps to confirm this, as set out in Section 14.

  1. Subject Matter, Duration, Nature and Purpose

The subject matter, duration, nature, purpose, categories of data subjects, and categories of Merchant Personal Data processed under this DPA are as set out in Annex 1, which incorporates by reference the Data Access & Processing Disclosure rather than restating it.

Processing continues for as long as the App is installed and the Agreement is in effect, and thereafter only as needed to complete deletion obligations under Section 13.

  1. Processing on Instructions

Shoptest will process Merchant Personal Data only on the Merchant's documented instructions, which consist of: (a) the Agreement and this DPA; (b) the Merchant's configuration and use of the Service; and (c) any further written instructions the Merchant issues, unless required to do otherwise by law.

If Shoptest believes an instruction infringes Applicable Data Protection Law, we will tell the Merchant and pause that instruction unless the law requires us to continue.

  1. Confidentiality of Personnel

Shoptest ensures that personnel authorized to process Merchant Personal Data are subject to confidentiality obligations and have received appropriate guidance on handling personal data.

  1. Security Measures

Shoptest implements technical and organizational measures appropriate to the risk. Merchant Personal Data is encrypted in transit (TLS) across all public and inter-service communication, and at rest using our cloud providers' default encryption. Access to production infrastructure is restricted to authorized personnel, and our infrastructure providers maintain SOC 2 Type II and ISO 27001 certifications.

A detailed technical and organizational measures annex is provided directly to Merchants as part of the signed Agreement, and is available on request at legal@shoptest.ai.

  1. Sub-processors

The Merchant grants Shoptest general authorization to engage Sub-processors to support delivery of the Service, subject to the conditions below. Our current sub-processors are listed at shoptest.ai/legal/subprocessors.

  • We will give notice of any new Sub-processor at least 30 days before it begins processing Merchant Personal Data.

  • The Merchant may object in writing within 15 days of notice; the parties will work in good faith to address the objection, and if unresolved, the Merchant may terminate the affected part of the Service as its exclusive remedy.

  • Shoptest remains responsible for each Sub-processor's compliance with obligations equivalent to those in this DPA.

  • The current list, including AI and email providers, is at shoptest.ai/legal/subprocessors and is incorporated into this DPA.

  1. Assistance with Data Subject Rights

Shoptest supports Merchant compliance with data-subject requests through Shopify's mandatory compliance webhooks described in the Disclosure (data request, customer redact, shop redact). Where a data subject contacts Shoptest directly regarding End Customer data, Shoptest will redirect them to the Merchant without undue delay.

  1. Personal Data Breach Notification

Shoptest will notify the Merchant without undue delay, and in any event within 72 hours of becoming aware of a Security Incident affecting Merchant Personal Data, and will provide the information we have at that time (nature, likely consequences, mitigation). We will update the Merchant as we learn more.

  1. Data Protection Impact Assessment Support

Shoptest will provide reasonably requested information to support the Merchant in carrying out a data protection impact assessment or prior consultation with a supervisory authority, to the extent the request relates to Shoptest's processing under this DPA.

  1. International Data Transfers

Merchant Personal Data is primarily hosted and processed in the United States (Render, Virginia — US East; Google Cloud Platform, us-east4), with browser-recording infrastructure hosted on Google Cloud Platform in europe-west2 (London, UK). Because the Company is established in the EEA, this means Merchant Personal Data originating in the EEA is transferred to the United States as part of ordinary processing under this DPA.

  • Google Cloud Platform: covered — Google's Cloud Data Processing Addendum, accepted by the Company as a Google Cloud customer, incorporates the EU Standard Contractual Clauses automatically.

  • Render: known gap, disclosed transparently. Render does not offer Standard Contractual Clauses. We disclose this directly rather than asserting a mechanism that isn't in place, and we are monitoring this — including the possibility of consolidating storage onto Google Cloud, which already provides SCC coverage.

  • Sentry (error monitoring, United States) and Stripe (payment processing, EU-registered account) are addressed in our sub-processor list.

  1. Deletion and Return of Data

While a Merchant's subscription is active, test-run history is retained according to the retention period of the Merchant's plan. If a Merchant cancels its subscription but does not uninstall the App, most Merchant data is retained, except that screenshots captured during test runs automatically expire after 60 days regardless of subscription status.

On uninstallation of the App, Shopify's shop/redact process triggers permanent erasure of all Merchant data within approximately 48 hours, regardless of subscription status at the time of uninstall.

At the Merchant's written request we will export available Merchant data (or return it in a reasonable machine-readable form) and/or delete it, including when the Merchant asks us to delete without uninstalling. We will also instruct sub-processors to delete that data, except where law requires retention (for example invoices).

  1. Audit Rights

On reasonable written notice, and no more than once per year (or more often if a regulator requires it or after a Security Incident), the Merchant may:

  • request a written description of our security measures;

  • request our then-current security questionnaire answers or equivalent (and a SOC 2 report or pen-test summary if we have one);

  • ask follow-up questions reasonably needed to confirm compliance with this DPA.

On-site inspection of production systems is not offered as a default. If a regulator or a Security Incident makes a deeper review necessary, the parties will agree a scoped review under confidentiality, in a way that does not put other customers' data at risk.

  1. Liability

Each party's liability under this DPA is subject to the limitation of liability set out in the Terms of Service.

  1. Term and General

This DPA takes effect on the date the Merchant accepts the Terms of Service and remains in effect for as long as Shoptest processes Merchant Personal Data. In case of conflict between this DPA and the Terms of Service on a data-protection matter, this DPA controls.

This DPA is governed by the laws of Poland, and disputes are subject to the exclusive jurisdiction of the competent court for the Company's registered seat in Poznań, Poland, consistent with the Terms of Service.

Annex 1 — Details of Processing

  • Categories of data subjects: Merchant staff/owner; the Merchant's End Customers (incidentally).

  • Categories of personal data: as described in the Data Access & Processing Disclosure.

  • Special categories of data: none — the Service is not designed to process special categories of personal data.

  • Nature and purpose of processing: automated storefront testing and monitoring.

  • Duration: for the term of the Agreement, plus the deletion window described in Section 13.

Categories of personal data typically processed:

  • Merchant staff / store owner: name, work email, phone, account and billing contacts

  • Shop business data: shop name, domain, address, plan, access token

  • Orders (last 60 days at install, then ongoing): totals, status, line items, channel, and browser IP where Shopify sends it — not customer profiles, and not card numbers

  • Catalog, discounts, themes (read), store content, Markets, aggregate analytics

  • Shopper-journey signals from our storefront pixel: hashed session id and page-type path (not raw URLs or customer profiles)

  • Test artifacts: screenshots, logs, and recordings of the public storefront

  • Incidental end-customer data if it appears on a public page or in a webhook we do not store as a customer record

Special categories: none. The Service is not designed to process them.

Annex 2 — Technical and Organizational Measures

A summary of our security posture:

  • Hosting: Render (Virginia) and GCP (Virginia + London)

  • Encryption: TLS in transit; provider-managed encryption at rest

  • Access: production access limited to authorized personnel; admin tools are role-gated

  • Monitoring: application error monitoring (Sentry); platform logs/metrics from the host

  • Backups: provider-managed backups on the hosting platform

  • Vendors: subprocessors listed at shoptest.ai/legal/subprocessors, including AI vendors used only for generation and diagnosis

A longer TOM sheet (access control, DR, vulnerability management) is available at legal@shoptest.ai.

Annex 3 — Sub-processors

See our current sub-processor list at shoptest.ai/legal/subprocessors.

1. Purpose and Scope

This document describes, in factual terms, what data the Shoptest application ("Shoptest", "the App", "we") can access, collect, and store when a Merchant ("Merchant", "you") installs Shoptest on a Shopify store, and what happens to that data during use of the App and after uninstallation.

2. Roles and Responsibilities

For data relating to your own business (shop details, catalog, orders, discounts, themes, content, analytics), Shoptest processes this data to provide the service you've purchased, acting as a Data Processor under Article 28 GDPR. Where Personal Data of End Customers is incidentally present, you remain the Data Controller.

You are responsible for having a lawful basis to process your End Customers' Personal Data, for disclosing the use of apps such as Shoptest in your own privacy policy, and for responding to End Customer rights requests.

3. Authorization Mechanism

Shoptest obtains access to your store exclusively through Shopify's standard app-installation flow: an OAuth 2.0 install flow where you explicitly grant the scopes listed below, an offline access token used to make authorized API calls, and webhook subscriptions that keep data in sync in near-real time.

4. OAuth Scopes Granted at Install

• read_products — product catalog, variants, inventory, selling plans; bulk import at install, ongoing sync via webhooks.

• write_products — modify products including metafields; requested for future functionality, not currently used.

• read_orders — order data; bulk import (60-day lookback), order webhooks, payment enrichment.

• read_themes — theme list and theme asset files; identify the main theme, read and cache selected files.

• read_script_tags — third-party script tags on the storefront; read during failure analysis.

• write_script_tags — create, update or delete script tags; requested for future functionality, not currently used.

• read_content — Online Store pages, blogs and articles; seed test URLs, support broken-link crawling.

• read_discounts — discount codes and automatic discounts; bulk import and webhook sync.

• read_reports — Shopify analytics / ShopifyQL reports; aggregate session and conversion metrics.

• read_markets — Shopify Markets configuration; buyer-country and market context for multi-market tests.

Not requested: read_customers / write_customers, read_checkouts, read_inventory (standalone), read_fulfillments, read_shipping, write_themes, or any scope beyond the ten above.

Note: write_products and write_script_tags are part of the install consent even though the corresponding write code paths are unused today — you're authorizing the capability, not just today's behavior. If this changes, we'll update this page and notify you.

5. Data We Access and Store

• Shop & account data: shop name, domain, owner email/name, business address, phone, timezone, currency, plan, and the access token that authorizes API calls.

• Products & collections: titles, variants, prices, inventory, images, handles, and collection membership — kept in sync via webhooks.

• Discounts: codes, types, rules, usage counts, and eligibility (customer segment IDs only — never full customer profiles).

• Orders: order totals, status, line items, sales channel, and (where available) IP address — from the last 60 days at install, then ongoing via webhooks. We do not have write access to orders. Order webhooks can technically include End Customer email/address, but our standard sync does not persist that into a customer record.

• Payment transactions: processor-level metadata (status, gateway, amount) for orders — never full card numbers, which Shopify's API never exposes to any app.

• Themes: read-only — we read theme files to detect changes and diagnose failures; we never modify your theme.

• Online Store content: page and blog titles/handles, used to generate test targets.

• Markets & pricing: currency and region configuration, for multi-market testing.

• Analytics: aggregate session and conversion metrics only — never individual-shopper records.

• Storefront automation: beyond the Admin API, we run automated browsers against your public storefront — visiting pages, running checkout-flow tests, capturing screenshots/logs, and crawling for broken links.

6. Data We Never Access

Customer profiles, draft orders/abandoned checkouts, inventory locations, fulfillment orders, shipping labels, staff accounts, theme modification rights, metaobjects/files/translations, and Shopify Payments payout details.

7. Personal Data and Your Rights

Shoptest subscribes to Shopify's three mandatory compliance webhooks:

• customers/data_request — returns any stored Personal Data held for a specified End Customer.

• customers/redact — anonymizes or deletes an End Customer's Personal Data on request.

• shop/redact — permanently erases all data for a shop, 48 hours after the App is uninstalled.

8. Data Storage, Security, and Sub-processors

Merchant data is hosted in the United States (Render, Virginia; Google Cloud Platform, Virginia) with browser-recording infrastructure in the UK (Google Cloud Platform, London). Data is encrypted in transit (TLS) and at rest (provider-managed encryption). Our current sub-processors are listed at shoptest.ai/legal/subprocessors.

9. International Data Transfers

Because our infrastructure is hosted in the US and UK while we're established in the EU, using the App as an EEA-based Merchant involves a transfer of personal data outside the EEA. This is addressed in our Data Processing Agreement, Section 12 — including a transparent disclosure that one of our hosting providers (Render) does not currently offer Standard Contractual Clauses.

10. Purpose Limitation

Data described here is accessed solely to provide the Shoptest service: automated QA and test-flow execution, store health monitoring, broken-link and page-speed monitoring, AI-assisted failure diagnosis, and billing. It is not used to build advertising profiles, sold to third parties, or repurposed beyond delivering and improving the Shoptest service.

11. Merchant Responsibilities

Installing Shoptest doesn't transfer your own compliance obligations to us. You remain responsible for maintaining a compliant privacy policy disclosing your use of Shoptest, having a lawful basis for your End Customer data, and responding to your End Customers' data-subject requests.

12. Caveats

This document reflects what the Shoptest codebase is built to access — not a guarantee of what Shopify returns for every shop, since Shopify's Protected Customer Data rules, plan limits, and API version can restrict which fields are actually returned.

13. Contact

Hyper Effekt sp. z o.o. ("Shoptest", "the Company"). Registered office: ul. 27 Grudnia 5/5A, 61-737 Poznań, Poland. Privacy contact: legal@shoptest.ai

Keep every sale you earn.

Ensure your path to purchase works flawlessly.

Set up in 15 minutes, and let Shoptest do the rest.

Keep every sale you earn.

Ensure your path to purchase works flawlessly.

Set up in 15 minutes, and let Shoptest do the rest.

Keep every sale you earn.

Ensure your path to purchase works flawlessly.

Set up in 15 minutes, and let Shoptest do the rest.

Keep every sale you earn.

Ensure your path to purchase works flawlessly.

Set up in 15 minutes, and let Shoptest do the rest.

Keep every sale you earn.

Ensure your path to purchase works flawlessly.

Set up in 15 minutes, and let Shoptest do the rest.